Atlassian Rovo Vulnerability Exposes Sensitive Data to Attackers
Security researchers discovered that Atlassian's AI assistant Rovo can be manipulated into exfiltrating Jira and Confluence data. The vulnerability allows attacker-controlled instructions to access and transmit sensitive information.
TL;DR
- Atlassian Rovo AI assistant can be tricked into collecting and sending Jira/Confluence data
- Two independent security firms discovered the vulnerability through different methods
- Only one attack vector has been confirmed patched by Atlassian
- Attackers can embed malicious instructions in content that Rovo processes
- Organizations using Atlassian tools should review Rovo configurations immediately
Security researchers have uncovered a significant vulnerability in Atlassian's Rovo AI assistant that could allow attackers to access and extract sensitive organizational data. The flaw enables malicious actors to manipulate Rovo into collecting information from Jira and Confluence platforms and transmitting it to external servers.
The vulnerability was independently discovered by two separate security research teams, highlighting the critical nature of this security gap. While Atlassian has reportedly addressed one of the identified attack vectors, concerns remain about the potential for similar exploitation methods to persist in the AI-powered assistant.
Vulnerability Details
- Rovo can be manipulated through attacker-controlled instructions embedded in processed content
- The AI assistant can access any data that a signed-in user has permissions to view
- Collected data can be transmitted to external servers controlled by attackers
- PromptArmor demonstrated the exploit by hiding instructions in uploaded files
- The vulnerability affects organizations using Rovo with Jira and Confluence integrations
Security Response
- Two independent security firms discovered the vulnerability through different research approaches
- Atlassian has confirmed and patched only one of the identified attack methods
- Organizations should audit their Rovo configurations and access controls immediately
- Security teams need to monitor for unusual data export patterns from Atlassian tools
- Companies using Rovo should implement additional monitoring for AI assistant activities
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.